yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2026-56022
Component Overview
Vulnerability Overview
Name
CVE-2026-56022
Source
NVD (
link
)
Debian (
link
)
Description
Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.640.
CWEs
CWE-308
Published Date
Jun 18, 2026
Updated Date
Aug 11, 2026
Workaround
-
Advisories
https://github.com/webmin/webmin/releases/tag/2.640
Release Notes
https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-169-02.json
VDB Entry
https://webmin.com/security/#webmin-prior-to-2640
Vendor Advisory
https://www.cve.org/CVERecord?id=CVE-2026-56022
VDB Entry
Analysis
#
Affected Component
Analysis
webmin
Exploitable
Vulnerability Ratings
#
6.9
CVSSv4
5.3
CVSSv31
NaN
other
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
webmin
yocto
kirkstone
1.850
Exploitable
webmin
yocto
master
2.653
Not Affected